Untrusted search path vulnerability in Atom Electron before 0.33.5 allows local users to gain privileges via a Trojan horse Node.js module in a parent directory of a directory named on a require line.
{
"github_reviewed_at": "2020-06-16T21:38:05Z",
"github_reviewed": true,
"cwe_ids": [
"CWE-426"
],
"nvd_published_at": null,
"severity": "HIGH"
}